Uh oh!
There was an error while loading. Please reload this page.
Conversation
Execution Profiles recorded for 1 job, triggered by
+1 · |
There was a problem hiding this comment.
Garnet runtime evidence gate: HOLD
The recorded workload changed. Strict policy requires human review for every workload destination delta.
This decision consumed the exact-head Garnet Runtime Review before evaluating the gate.
| Evidence | Value |
|---|---|
| PR head | a39642519deefda2804d6d335f1e4bb6763a6fa2 |
| Compared with | 25c8e4f4c6e026a57d6e3873d484b7b5b6f1868b |
| Recorded jobs | 1 |
| Changed jobs | 1 |
| Workload destinations | +1 / -0 |
| Process chains | 23 |
| Total destinations | 11 |
| Runner background | +3 / -0 (non-gating) |
Recorded workload diff
@@ 25c8e4f (previous) vs a396425 (current) @@
Runner.Worker
└─ MainThread
├─ sh
│ └─ go
│ ├─ ○ proxy.golang[.]org
│ ├─ ○ storage.googleapis[.]com
+ │ └─ ○ sum.golang[.]org
├─ ○ api.github[.]com
├─ ○ github[.]com
└─ ○ release-assets.githubusercontent[.]com
systemd (runner background · +3)
├─ hosted-compute-
+ │ ├─ ○ 140.82.113.24+ │ ├─ ○ 140.82.114.24+ │ ├─ ○ glb-2a3c35-public-internal.githubapp[.]com (github infra)
│ └─ ○ localhost (dns resolver)
└─ systemd-network
└─ ○ ip6-allroutersGate policy
- Fail closed when exact-head evidence or a same-PR comparison is missing.
- CLEAR only when the recorded workload has no changed job and no added, removed, or vanished workload destination.
- Ignore runner-background rotation for the decision.
- HOLD every workload delta for a human; this gate does not infer that a new CDN, registry, or checksum endpoint is safe.
Policy result is bound to commita39642519deefda2804d6d335f1e4bb6763a6fa2.
Two-stage fork-only replay of cli#14204. The first run establishes a same-PR pre-change runtime profile; the next commit removes the temporary marker and applies only the original upstream go.mod/go.sum patch. The final reviewed diff will contain only the dependency update. No upstream writes.